Automate Security Updates on Debian with Unattended‑Upgrades: A Practical Guide
Automated security patching on Debian is simple with the unattended‑upgrades package. This guide walks you through installing, configuring, testing, and monitoring the feature so you can keep your systems secure without manual intervention.
03 Jul 2026, 06:09 UTC

Desired Outcome
Enable a fully automated, secure‑only patching process on Debian that downloads, installs, and optionally reboots with minimal manual oversight.
Prerequisites
- Debian 12 (Bookworm) or later, running as a non‑root user with
sudoprivileges. - Active APT repositories that expose security updates (e.g.,
deb http://deb.debian.org/debian bookworm-security main contrib non-free). - Disk space sufficient for
/var/cache/apt/archives(recommended > 1 GB). - Optional:
apt-listchangesinstalled if you want email notifications.
Step‑by‑Step Procedure
- Install the package
# Run as root or with sudo sudo apt update sudo apt install unattended-upgradesInstallation pulls the
unattended-upgradesbinary and default config files. - Verify the timer service is enabled
systemctl status apt-daily-upgrade.timerThe timer should be
enabledandactive (waiting). It triggers theapt-daily-upgrade.servicetwice a day. - Configure which updates are applied
Open
/etc/apt/apt.conf.d/50unattended-upgradeswith your editor:// Only security updates Unattended-Upgrade::Allowed-Origins { "Debian:stable:Security"; }; // Do not upgrade from the main repository Unattended-Upgrade::Allowed-Origins { ""; }; // Enable email notifications (requires apt-listchanges) Unattended-Upgrade::Mail "root@localhost"; Unattended-Upgrade::Mail-Report "on-change"; // Optional: automatic reboot after kernel update Unattended-Upgrade::Automatic-Reboot "true"; Unattended-Upgrade::Automatic-Reboot-Time "02:00";Adjust the
Allowed-Originsblock to match your release and security component names. The example above restricts updates to security packages only. - Integrate apt‑listchanges for change logs
sudo apt install apt-listchangesUnattended‑upgrades will now call
apt-listchangesand email the admin if changes are detected. - Test the configuration
sudo unattended-upgrade --dry-run --debugThe command simulates the upgrade process, printing which packages would be installed and which repository sources they come from. Verify the output matches expectations.
- Enable the timer (if not already)
sudo systemctl enable --now apt-daily-upgrade.timerNow the timer will fire automatically.
- Monitor logs
sudo less /var/log/unattended-upgrades/unattended-upgrades.logLook for entries such as
Installing: package-nameandReboot required: yes.
Expected Checks
- After a timer run,
systemctl status apt-daily-upgrade.serviceshould showactive (exited)with a0exit code. - The log file should contain a
Start timeandEnd timepair, and anyReboot requiredflags. - Running
dpkg -l | grep '^ii' | awk '{print $2}' | xargs apt list --installed | grep -i securityshould list only security‑patched packages. - Check disk usage:
df -h /var/cache/apt/archivesshould not approach100%.
Recovery Options
- If a package fails, the log will contain the error. Use
sudo unattended-upgrade --dry-run --debugto identify the culprit before re‑enabling the timer. - To temporarily suspend automated upgrades, disable the timer:
sudo systemctl disable apt-daily-upgrade.timer. - In case of repeated failures, clear the cache:
sudo apt cleanand re‑run the dry‑run. - For critical services, schedule a maintenance window and set
Unattended-Upgrade::Automatic-Reboot-Timeto a low‑traffic hour.
Limitations & Monitoring
- Unattended‑upgrades only handles packages from APT sources. Custom repositories or PPAs are ignored unless added to
Allowed-Origins. - Proprietary drivers (e.g., NVIDIA) may break if updated automatically; consider excluding them via
Unattended-Upgrade::Package-Blacklist. - Automatic reboots can disrupt long‑running services. Use
systemd-inhibitorUnattended-Upgrade::Automatic-Rebootwisely. - Monitor
/var/log/unattended-upgrades/unattended-upgrades.logweekly or integrate with log‑management tools.
Conclusion
With a few configuration steps, Debian’s unattended-upgrades turns manual security patching into a reliable, low‑maintenance process. By testing with --dry-run and monitoring logs, you can keep your systems secure while avoiding surprises.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.